In February 2024, Google and Yahoo fundamentally changed email marketing forever by requiring authentication for bulk senders. One year later, the rules are fully enforced. Here's everything you need to know to stay compliant in 2025.
The Requirements at a Glance
Google (Gmail) Requirements
| Requirement | All Senders | Bulk Senders (5,000+/day) |
|---|---|---|
| SPF or DKIM | Required | Required |
| SPF AND DKIM | Recommended | Required |
| DMARC | Recommended | Required (at least p=none) |
| One-Click Unsubscribe | Recommended | Required |
| Spam Rate | < 0.3% | < 0.1% |
| Forward-Confirmed rDNS | Required | Required |
| TLS Encryption | Required | Required |
Yahoo Requirements
Yahoo's requirements mirror Google's with slight variations:
- SPF and DKIM required for bulk senders
- DMARC required with at least p=none
- Easy unsubscribe mechanism
- Honor unsubscribes within 2 days
- Spam complaint rate monitoring
Understanding "Bulk Sender" Status
Who Qualifies as a Bulk Sender?
You're classified as a bulk sender if you send 5,000+ messages to Gmail addresses in a single day. This is:
- Calculated per sending domain, not per IP
- Based on messages to Gmail/Google Workspace users
- A running threshold - exceeding once triggers requirements
Common Bulk Senders
- Marketing teams sending newsletters
- E-commerce sending order confirmations and shipping updates
- SaaS companies sending product notifications
- Financial services sending statements and alerts
- Healthcare sending appointment reminders
Authentication Requirements Explained
SPF (Sender Policy Framework)
Purpose: Declares which servers can send email for your domain.
Requirement: Must pass SPF checks for your sending IP.
Implementation:
v=spf1 include:_spf.google.com include:sendgrid.net -all
Common Mistakes:
- Exceeding 10 DNS lookup limit
- Using ~all instead of -all
- Forgetting to add new sending services
DKIM (DomainKeys Identified Mail)
Purpose: Cryptographically signs emails to verify they haven't been modified.
Requirement: All bulk emails must be DKIM-signed with at least 1024-bit keys.
Implementation:
- Enable DKIM in your email provider
- Add DKIM public key to your DNS
- Verify signature is applied to outgoing mail
Best Practices:
- Use 2048-bit keys (more secure)
- Rotate keys annually
- Monitor DKIM failures in DMARC reports
DMARC (Domain-based Message Authentication)
Purpose: Tells receivers what to do when SPF/DKIM fail and provides reporting.
Requirement: Must have DMARC record with at least p=none.
Recommended Implementation:
v=DMARC1; p=reject; rua=mailto:[email protected]; pct=100
Progression Path:
- Start with p=none (monitoring)
- Move to p=quarantine after 2-4 weeks
- Achieve p=reject for full protection
Unsubscribe Requirements
One-Click Unsubscribe
Bulk senders must include:
- List-Unsubscribe-Post header: Enables one-click unsubscribe
- List-Unsubscribe header: Provides unsubscribe mechanism
- Visible unsubscribe link: Clear link in email body
Required Headers:
List-Unsubscribe: <https://example.com/unsubscribe?id=123>
List-Unsubscribe-Post: List-Unsubscribe=One-Click
Processing Time
- Google: Must process unsubscribes within 2 days
- Yahoo: Must honor requests within 2 days
- Best Practice: Process immediately (within minutes)
Spam Rate Requirements
Google's Spam Thresholds
| Spam Rate | Consequence |
|---|---|
| < 0.1% | Ideal - full deliverability |
| 0.1% - 0.3% | Warning zone - may see throttling |
| > 0.3% | Delivery issues - emails to spam/blocked |
How to Monitor
- Google Postmaster Tools: Free monitoring dashboard
- Set up: Add your domain at postmaster.google.com
- Monitor daily: Watch spam rate trends
Reducing Spam Complaints
- Only send to engaged subscribers
- Honor unsubscribes immediately
- Set expectations during signup
- Send relevant, valuable content
- Make unsubscribe easy to find
Technical Requirements
Valid PTR Records (rDNS)
Your sending IP must have:
- Forward-confirmed reverse DNS
- PTR record that resolves back to your IP
Example:
IP: 203.0.113.1
PTR: mail.yourdomain.com
A (mail.yourdomain.com): 203.0.113.1
TLS Encryption
- All connections must support TLS 1.2 or higher
- Opportunistic TLS at minimum
- Most email providers handle this automatically
RFC 5322 Compliance
Emails must be properly formatted according to RFC 5322:
- Valid From header
- Valid Date header
- Message-ID present
- Proper line length (998 characters max)
Compliance Checklist
Before Sending Bulk Email
- SPF record published and validated
- DKIM enabled and signing emails
- DMARC record published (minimum p=none)
- List-Unsubscribe headers configured
- One-click unsubscribe working
- rDNS configured for sending IPs
- TLS enabled for email transmission
- Google Postmaster Tools configured
- Spam rate below 0.1%
Ongoing Maintenance
- Monitor DMARC reports weekly
- Check spam rate in Postmaster Tools daily
- Process unsubscribes within 2 days
- Update SPF when adding new senders
- Rotate DKIM keys annually
- Clean email list regularly
Troubleshooting Common Issues
Emails Going to Spam
- Check authentication (SPF, DKIM, DMARC all passing?)
- Review spam rate in Postmaster Tools
- Verify sender reputation
- Check for blacklisting
- Review email content for spam triggers
Bounce Rates Increasing
- Clean your email list
- Implement double opt-in
- Remove inactive subscribers
- Check for invalid email formats
DMARC Failures
- Review DMARC reports for failure sources
- Identify unauthorized senders
- Update SPF to include legitimate services
- Enable DKIM for all sending platforms
Tools and Resources
Free Tools
- StopSpoofingMe Domain Scanner - Check your authentication
- Google Postmaster Tools - Monitor sender reputation
- MXToolbox - DNS and email testing
Our Services
- Free Domain Scan - Check your compliance status
- DIY Implementation Guide - Step-by-step setup
- Professional Setup - Expert configuration
The era of unauthenticated bulk email is over. Organizations that embrace these requirements are seeing improved deliverability, better engagement, and stronger sender reputation.
Need help achieving compliance? Contact our team for personalized guidance.
Related Topics
Ready to Secure Your Email?
Check your domain's email security status with our free scanner, or get professional help setting up DMARC, SPF, and DKIM.